Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-01-03 CVE-2021-24893 Improper Input Validation vulnerability in Stars Rating Project Stars Rating
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.
network
low complexity
stars-rating-project CWE-20
7.5
2022-01-03 CVE-2021-45916 Improper Input Validation vulnerability in SMR Shenwang Endpoint Protection Security System
The programming function of Shockwall system has an improper input validation vulnerability.
low complexity
smr CWE-20
3.5
2022-01-03 CVE-2021-30278 Improper Input Validation vulnerability in Qualcomm products
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
local
low complexity
qualcomm CWE-20
5.5
2021-12-28 CVE-2021-44832 Improper Input Validation vulnerability in multiple products
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server.
network
high complexity
apache oracle cisco fedoraproject debian CWE-20
6.6
2021-12-27 CVE-2021-45687 Improper Input Validation vulnerability in Raw-Cpuid Project Raw-Cpuid
An issue was discovered in the raw-cpuid crate before 9.1.1 for Rust.
network
low complexity
raw-cpuid-project CWE-20
critical
9.8
2021-12-27 CVE-2021-45711 Improper Input Validation vulnerability in Simple Asn1 Project Simple Asn1 0.6.0
An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust.
network
low complexity
simple-asn1-project CWE-20
7.5
2021-12-26 CVE-2021-41788 Improper Input Validation vulnerability in Mediatek products
MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding.
network
low complexity
mediatek CWE-20
7.5
2021-12-23 CVE-2021-38015 Improper Input Validation vulnerability in multiple products
Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
network
low complexity
google fedoraproject debian CWE-20
8.8
2021-12-23 CVE-2021-4059 Improper Input Validation vulnerability in multiple products
Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-20
6.5
2021-12-20 CVE-2021-41561 Improper Input Validation vulnerability in Apache Parquet-Mr
Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files.
network
low complexity
apache CWE-20
7.5